Preston and I had the rare honor of speaking with SSH Communications founder, Tatu Ylönen about IoT device security. For those of you who don’t know, Tatu Ylönen is the inventor and original programmer of the SSH protocol. There’s absolutely no one in the world more qualified to speak on security than Tatu.
He single-handedly protected us all from plain text transmissions and essentially destroyed the old Telnet protocol for good. In this podcast, we discuss the importance of IoT security. IoT security has traditionally been ignored because the few devices that existed weren’t particularly vulnerable to hacking either because no one cared or no one had access to the hardware and software to do so. That’s no longer true. Everyone has access to exploitation tools and the time for focusing on a more secure IoT has arrived.
For IoT manufacturers, you should listen carefully to Tatu’s advice and insights. Some of these devices and networks carry high-value data, including possibly personal data and that needs to be protected.
Length: 14:43 minutes. Format: MP3. Rating: G for all audiences.
A special thanks to Tatu Ylönen and to the Nadel Phelan agency for connecting us.
Preston and I discussed the new NIST password guidelines with our regular guest, Richard Henderson of Absolute. In this podcast, we cover the guidelines and what they might mean to you, especially if you’re a web application developer. If you’re not a developer, you might still have an opinion as a user. The new guidelines are a very positive step forward for government agencies and for private ones as well. Password security has been taken for granted for too long but can no longer be ignored. Security experts can spout all the best practices that they can think of but those best practices are only good if they’re put into practice.
We also discuss the costs that might arise from retrofitting current applications vs. tackling the problem from the beginning. Richard has some very important insights to consider when going forward with these guidelines.
Length: 28:20 minutes. Format: MP3. Rating: G for all audiences.
You might remember Richard Henderson, Absolute’s Global Security Strategist from our March 21, 2017, podcast covering Enterprise Security Trends. Richard joins us again to discuss what to do after you discover a breach and why the first 48 hours are so important. You’ll also hear Preston and me disagree about first steps to take after you discover a breach.
In this podcast, Richard gives us an overview of how companies should handle breach announcements, responsibility for breaches, and his best advice for companies that have experienced a breach.
Length: 20:31 minutes. Format: MP3. Rating: G for all audiences.
We’re hoping that Richard will continue to join us on a regular basis to discuss timely security topics that affect you and your business operations. If you have questions that you’d like to have us ask Richard or any of our guests, please use the Contact Form and let us know. We’re also open to new show topics and guests.
Preston and I had a good discussion with Commvault‘s Senior Director of Product Management, Don Foster. When most people, and possibly you, think of Commvault, you think backup and restore. But Commvault is much more than simple backup and restore activities; it covers the entire gamut of data protection for your business. Commvault is a common word for IT old-timers and newcomers alike since it’s been around for 30 years.
In this podcast, we cover data protection as it relates to backup, restore, business continuity, recovery, and more. Data protection is a company’s consistent defense against theft, data exfiltration, data loss, insider threats, ransomware, and disasters. Disaster recovery is another huge chunk of what Commvault does. We touch on every aspect of enterprise data protection in this podcast.
You have to remember that not all security topics deal with passwords, encryption, and policies–some of it has to do with the actual mechanics of protecting your data. Think disaster recovery.
Think about what Commvault offers you. We’ve all had backups and restores fail on us–even after multiple checks. What Commvault offers is the assurance that your data doesn’t have to be restored to its original backup point to be readable and usable, when the worst happens. Don explains this service further in the podcast. We also cover mobile data protection in the podcast. This one is a few minutes longer than our average podcast but I think you’ll agree that your time will be well spent by listening to it.
Length: 27:45 minutes. Format: MP3. Rating: G. License: CC BY.
In this podcast, Preston, our guest John Michelsen, CPO of Zimperium, and I discuss mobile security and extrapolate what’s happening in that space to what’s happening, and about to happen, with IoT security. We touch on monitoring, general security, costs, and the bigger problem of security implementation on devices that until recently were used based on an “air of trust.”
April is our “Month of Preventing Surprises” and this podcast kicks off that topic for The SecurityNOW Show. How awkward would it be to move headlong into a large IoT implementation only to realize that someone has easily hacked your devices and siphoned off your data? Surprise!
Mobile security has come a long way in the past two years with the adoption of higher security measures from vendors and third parties, such as per-app VPN, two-factor authentication, and containerization. IoT vendors will have to step up and enable encryption, use multi-factor authentication, and wipe or brick devices that have been compromised or moved. The Internet of Things may very well be security’s biggest challenge yet, not only because of the sheer numbers of devices but also because of device diversity.
Preston, John, and I just touch the surface of these topics in this podcast but stay tuned for more from all three of us on IoT security.
Length: 20:45 minutes. Format: MP3. Rating: G for all audiences.
Preston and I decided to discuss the latest in privacy at Shiloh’s Restaurant in Broken Arrow a few days ago. As you’ll hear on the podcast, we perhaps needed more privacy. I apologize for the background noise but you can think of it as a lesson in security in that our conversation at times was obfuscated by surrounding conversations and music that didn’t seem to start playing until we hit the Record button. Such is life. We deal with our surroundings all the time, which makes me believe that our choice of venue for this podcast was the perfect setting to have a conversation on privacy. It works on many levels.
During our talk, Preston and I ponder the outcome of the Congressional decision to remove current privacy legislation and put it firmly in the hands of someone grossly unqualified to make such a decision. In any case, I think we need to join together in embracing privacy much like the EU has with GDPR, which we’ve discussed in another podcast.
Stay tuned for more commentary as the situation develops.
Length: 19:26 minutes. Format: MP3. Rating: G for all audiences.
Seriously, please write your Congressman and your Senators about this. It’s too important to leave in unqualified hands.
Preston and I had the pleasure of speaking with BigID CEO Dimitri Sirota about General Data Protection Regulation (GDPR) and what it means to American businesses. We discussed several topics surrounding compliance such as dealing with GDPR and EU businesses, costs of compliance, pain points, where to find more information, and some solutions.
The main point of GDPR is to give users control of their personal data. For one, GDPR requires explicit permission from the data owner to allow personal data to be used. GDPR also includes the right to be forgotten or erased, which is a big topic of discussion for Preston and me.
In the US, public records can be scraped by anyone with the money to pay for the service. If you don’t understand what I mean, open a browser and type in your name. Google will return a few dozen hits with links to companies that will sell all public information about you to scammers, thieves, blackmailers, and others who have less than savory intentions.
These sources have access to your home address, former addresses, family member names, ages, dates of birth, court cases, arrests, traffic violations, and much more. You’ll be shocked. I’ve attempted to remove myself from as many of these lists as possible because I feel it’s a violation of my privacy and of my right to privacy. The European Union (EU) agrees.
Length: 25:44 minutes. Format: MP3. Rating: G for all audiences.
I have to apologize for my sound quality. It only affected my microphone. My gain was too high. Preston and I didn’t discover the problem until after the interview, which is really too late to do anything about it. I tried to fix it but had little luck in doing so. We have since resolved the issue.